A Cross-Platform Secure USB Flash Drive Management Method and System

By building a multi-block file system and setting a role permission list, the problem of insufficient data security of USB disks is solved, cross-platform fine-grained access control and data protection is realized, and the security and compatibility of USB disks are enhanced.

CN119577857BActive Publication Date: 2025-07-22BEIJING ELECTRONICS SCI & TECH INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411606345.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-12
Publication Date
2025-07-22
Estimated Expiration
2044-11-12

AI Technical Summary

Technical Problem

The existing USB disk data is insufficient, and fine-grained access control cannot be achieved in a multi-platform environment, and the lack of an effective authentication mechanism leads to a high risk of data leakage.

Method used

Build a file system including a secure information area, an extended metadata area, a data area and a control area, randomly generate keys and use public key encryption technology to set up role permission lists and operation permission lists to achieve fine-grained access control.

Benefits of technology

Ensure the confidentiality and integrity of USB drive data, prevent unauthorized access and tampering, support multi-platform compatibility, simplify permission management, improve information exchange efficiency and reduce the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119577857B_ABST
    Figure CN119577857B_ABST
Patent Text Reader

Abstract

The present invention discloses a cross-platform secure USB flash drive management method, which includes: constructing a file system including a security information area, an extended metadata area, a data area, and a control area and placing it into a common USB flash drive to obtain a secure USB flash drive; randomly generating a key for the secure USB flash drive, selecting shared users and setting corresponding permissions, generating a role permission list and an operation permission list, and storing them in the control area and the extended metadata area respectively; encrypting the key with the corresponding user public key obtained based on the shared users and the registration public key generated by the registered users respectively to obtain encrypted content; saving the encrypted content to the security information area to complete the registration of the secure USB flash drive; decrypting the encrypted content based on the private key of the user to be authenticated, and completing the authentication of the secure USB flash drive based on the decryption result; after the authentication is passed, obtaining the user identity based on the role permission list; performing corresponding data operations on the data area based on the user identity and the operation permission list. This enables the data stored on the USB flash drive to be protected from unauthorized access, tampering, and malicious attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and more particularly to a cross-platform secure USB flash drive management method and system. Background Art

[0002] At present, due to its plug-and-play, portable and lightweight, and easy-to-operate characteristics, the USB flash drive has become an indispensable data exchange and transmission tool in daily life. However, the data security was not considered in the initial design, resulting in any computer being able to easily access the USB flash drive and the data therein, and the loss of the USB flash drive may lead to data leakage. Therefore, protecting the data security on the USB flash drive has become crucial. Currently, two solutions are generally adopted: hardware protection and software encryption.

[0003] The hardware protection solution is a strategy to enhance the data security of the USB flash drive by integrating specific hardware devices. For example, a fingerprint authentication module is introduced, and only the verified fingerprint can authorize access to the data in the USB flash drive; or an encryption chip is integrated, and the user is required to enter the correct key to decrypt the ciphertext data in the USB flash drive to obtain the plaintext information. However, adopting this hardware protection solution not only requires modifying the original USB flash drive structure, but also may increase the user's usage cost due to the introduction of additional hardware devices.

[0004] The software protection solution is a strategy to ensure data security by software encryption technology when the host accesses the USB flash drive. For example, designing a secure file system and using encryption technology to protect the data stored therein to prevent unauthorized access; or intercepting the USB flash drive driver of the system and encrypting the data in real time during the USB communication process to effectively protect the data in the USB flash drive from being illegally obtained or tampered with. In the software-based protection solution, currently, the x86 hardware environment is taken as the research object, and solutions are proposed for the windows or Linux systems. With the construction of domestic informatization, a solution that can be compatible with multiple platforms and multiple systems and provide a unified operation and usage method for users is needed. At the same time, the current solutions mainly focus on using cryptographic technology to protect the data on the USB flash drive, but often lack an authentication mechanism, and cannot confirm the details of the host and the USB flash drive, resulting in the inability to control the usage environment and operation permissions of the USB flash drive. Moreover, the design of data sharing among multiple users and file access control is relatively rough, resulting in unreasonable allocation of information usage permissions during use.

[0005] Therefore, how to avoid unauthorized access, tampering, and malicious attacks on the USB flash drive data is an urgent problem that needs to be solved by those skilled in the art. Summary of the Invention

[0006] In view of this, the present invention provides a cross-platform secure USB flash drive management method and system, which realizes fine-grained access control for USB flash drive data, so that the data stored on the USB flash drive is protected from unauthorized access, tampering and malicious attacks.

[0007] To achieve the above object, the present invention adopts the following technical solutions:

[0008] A cross-platform secure USB flash drive management method, including:

[0009] Construct a file system including a security information area, an extended metadata area, a data area and a control area and place it into a common USB flash drive to obtain a secure USB flash drive;

[0010] Randomly generate a key for the secure USB flash drive, select shared users and set corresponding permissions, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively;

[0011] Based on the shared users, encrypt the key respectively with the corresponding user public key obtained and the registration public key generated by the registered users to obtain encrypted content;

[0012] Save the encrypted content to the security information area to complete the registration of the secure USB flash drive;

[0013] Based on the private key of the user to be authenticated, decrypt the encrypted content, and complete the authentication of the secure USB flash drive based on the decryption result;

[0014] After the authentication is passed, obtain the user identity based on the role permission list;

[0015] Based on the user identity and the operation permission list, perform corresponding data operations on the data area.

[0016] Preferably, the role permission list specifically includes:

[0017] Administrator: Can use the secure USB flash drive and can change the user role settings;

[0018] Prohibited user: Cannot use the secure USB flash drive;

[0019] Ordinary user: Can use the secure USB flash drive and cannot change the user role settings;

[0020] Restricted user: Can use the secure USB flash drive and cannot view, create and operate the data information with specified restricted conditions in the secure USB flash drive.

[0021] Preferably, the administrator is a registered person, has full control rights over the intermediate files generated by the operations of the ordinary users and the restricted users, and can set other users as administrators;

[0022] Both the ordinary user and the restricted user can set the operation permissions of other users on the intermediate file except the administrator.

[0023] Preferably, the registration process further includes:

[0024] Encrypt the identifier using a symmetric encryption algorithm based on the key, obtain the encrypted identifier, and save it to the security information area.

[0025] Preferably, obtaining the encrypted content specifically includes:

[0026] Encrypt the key respectively based on all the user public keys to obtain multiple shared encryption results;

[0027] Encrypt the key based on the registration public key to obtain the registration encryption result;

[0028] The registration encryption result and the shared encryption results together constitute the encrypted content;

[0029] The encrypted content is saved to the corresponding area of the security information area.

[0030] Preferably, the security USB flash drive authentication specifically includes:

[0031] Decrypt the registration encryption result based on the private key of the user to be authenticated to obtain the first pre-decryption key;

[0032] Determine whether the correct identifier is obtained by decrypting the encrypted identifier based on the first pre-decryption key;

[0033] If so, it means that the security USB flash drive has been shared with the user to be authenticated and the key has been obtained;

[0034] If not, decrypt the shared encryption results based on the private key. After traversing all the shared encryption results, determine whether the correct key is obtained;

[0035] If so, it indicates that the user to be authenticated is the shared user and the authentication is passed;

[0036] If not, it indicates that the authentication fails and the security USB flash drive cannot be used.

[0037] Preferably, performing the corresponding data operation on the data area specifically includes:

[0038] Determine the user identity of the user to be authenticated based on the role permission list and the shared encryption results;

[0039] If the user identity is the administrator, all data information in the security USB flash drive can be operated;

[0040] If the user identity is the ordinary user, perform corresponding operations on the data information in the secure USB flash drive based on the permission operation list;

[0041] If the user identity is the prohibited user, the secure USB flash drive cannot be used;

[0042] If the user identity is the restricted user, the data information with specified restricted conditions in the secure USB flash drive cannot be viewed, created, or operated on.

[0043] Preferably, when the shared user stores a file based on the secure USB flash drive, a shared permission list is generated based on the stored file and stored in the extended metadata area;

[0044] Before other users other than the administrator operate on the stored file, it is determined whether they have the operation permission based on the shared permission list. If they have the operation permission, they can perform the corresponding operation; otherwise, they cannot perform the operation.

[0045] Preferably, the extended metadata area stores the verification hash value of the file. When the content of the file changes, the hash value of the corresponding changed file is calculated and saved to the file verification area.

[0046] A cross-platform secure USB flash drive management system includes: a secure USB flash drive construction module, a permission setting module, a registration module, an authentication module, and a data operation module;

[0047] The secure USB flash drive construction module is used to construct a file system including a security information area, an extended metadata area, a data area, and a control area and place it into an ordinary USB flash drive to obtain a secure USB flash drive;

[0048] The permission setting module is used to randomly generate the key of the secure USB flash drive, select shared users and set permissions correspondingly, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively;

[0049] The registration module is used to encrypt the key based on the corresponding user public key of the shared user and the registration public key generated by the registered user respectively to obtain the encrypted content; the encrypted content is saved to the security information area to complete the registration of the secure USB flash drive;

[0050] The authentication module is used to decrypt the encrypted content based on the private key of the user to be authenticated and complete the authentication of the secure USB flash drive based on the decryption result;

[0051] The data operation module is used, after authentication is passed, to obtain the user identity based on the role permission list; perform corresponding data operations on the data area based on the user identity and the operation permission list.

[0052] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a cross-platform secure USB flash drive management method and system, which has the following beneficial effects:

[0053] 1. Ensure the confidentiality and integrity of USB flash drive data based on a secure and controllable file system; through an authorization method, only legitimate platforms or users who have passed authentication can access the data in the secure USB flash drive. By setting up a role permission list and an operation permission list, fine-grained access control of the USB flash drive data is realized, so that the data stored on the USB flash drive is protected from unauthorized access, tampering, and malicious attacks.

[0054] 2. By randomly generating a key and encrypting the key using public key encryption technology, it is ensured that only users with the corresponding private key can decrypt and access the data in the USB flash drive, effectively preventing unauthorized data access and enhancing data confidentiality.

[0055] 3. Based on the role permission list and the operation permission list, the administrator can assign specific operation permissions to different shared users. This mechanism allows for setting detailed access control policies according to the actual needs of users, achieving more refined data protection, and at the same time simplifying the permission management process.

[0056] 4. By configuring independent access permissions for each shared user, the same USB flash drive can be used by multiple users in different levels, which not only ensures the information exchange efficiency during teamwork but also avoids the risk of data leakage caused by excessive permissions.

[0057] 5. Due to the adoption of a standard file system structure and a common encryption algorithm (such as AES), this solution can run on multiple operating system platforms, including but not limited to Windows, Mac OS X, and Linux, etc., greatly improving its application scope and convenience.

[0058] 6. The present invention stores detailed permission configuration information and log records in the control area, which is convenient for retrospective analysis afterwards, helps to discover potential threats or violations, and enables timely measures to be taken to deal with them. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0060] Figure 1 It is a schematic flowchart of a cross-platform secure USB flash drive management method provided by the present invention.

[0061] Figure 2 Schematic diagram of the file system format provided by the present invention.

[0062] Figure 3 Flowchart of the security USB flash drive authentication provided by the present invention.

[0063] Figure 4 Schematic diagram of the structure of a cross-platform security USB flash drive management system provided by the present invention.

[0064] Figure 5 Schematic diagram of the overall framework of the security USB flash drive provided by the present invention. Specific implementation manners

[0065] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0066] Embodiment 1

[0067] As Figure 1 shown, an embodiment of the present invention discloses a cross-platform security USB flash drive management method, including:

[0068] Construct a file system including a security information area, an extended metadata area, a data area, and a control area and place it in a common USB flash drive to obtain a security USB flash drive;

[0069] Randomly generate a key for the security USB flash drive, select shared users and set corresponding permissions, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively;

[0070] Encrypt the key based on the corresponding user public key obtained from the shared user and the registration public key generated by the registered user respectively to obtain encrypted content;

[0071] Save the encrypted content to the security information area to complete the registration of the security USB flash drive;

[0072] Decrypt the encrypted content based on the private key of the user to be authenticated, and complete the authentication of the security USB flash drive based on the decryption result;

[0073] After the authentication is passed, obtain the user identity based on the role permission list;

[0074] Perform corresponding data operations on the data area based on the user identity and the operation permission list.

[0075] Embodiment 2

[0076] An embodiment of the present invention discloses a cross-platform secure USB flash drive management method, including:

[0077] As Figure 2 shown, construct a file system including a security information area, an extended metadata area, a data area, and a control area and place it into a common USB flash drive to obtain a secure USB flash drive:

[0078] Preferably, construct a file system including a security information area, an extended metadata area, a data area, and a control area as the secure and controllable file system of the present invention. Among them, the security information area is used to store the registered public key and the key encrypted by the user's public key, which can not only ensure the confidentiality of the USB flash drive data but also realize sharing among different users. It also stores a marker, and the marker is stored using the key of the USB flash drive. Only users with the key of the USB flash drive can obtain the correct marker and use the USB flash drive correctly; the extended metadata area adds a file hash value on the basis of the traditional file system to ensure the integrity and non-tampering of the data; the data area encrypts the stored data using a symmetric encryption algorithm to ensure the confidentiality of the stored data; the control area is used to store the role permission list of the file and implement role access control based on the role permission list.

[0079] Preferably, the secure and controllable file system further includes a boot sector for the computer to understand the layout and operation method of the file system.

[0080] Preferably, the boot sector, the extended metadata area, the data area, and the control area are all encrypted and stored using the key of the secure USB flash drive.

[0081] Preferably, the extended metadata area stores the verification hash value of the file. When the content of the file changes (such as addition, deletion, modification, query, etc.), the hash value of the corresponding changed file is updated and saved to the file verification area, and the integrity and non-tampering of the data stored on the secure USB flash drive are ensured by using the verification of the hash value.

[0082] Preferably, the integrity, availability, confidentiality, and authenticity of the secure USB flash drive data are ensured based on the secure and controllable file system.

[0083] Randomly generate the key of the secure USB flash drive, select shared users and set corresponding permissions, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively:

[0084] Preferably, the role permission list records the roles corresponding to the known shared users and the permissions owned by the roles and stores them in the control area. After the secure USB flash drive is successfully authenticated, the USB flash drive usage permissions of the user are judged based on the role permission list.

[0085] Preferably, the user role or user identity includes: administrator, prohibited user, ordinary user, and restricted user.

[0086] Preferably, the role permission list specifically includes:

[0087] Administrator: Can use the secure USB drive and can change the user roles.

[0088] Prohibited user: Cannot use the secure USB drive.

[0089] Ordinary user: Can use the secure USB drive but cannot change the user roles.

[0090] Restricted user: Can use the secure USB drive but cannot view, create, and operate on the data information with specified restricted conditions in the secure USB drive.

[0091] Preferably, the administrator is a registered person and has full control over the intermediate files generated by the operations of ordinary users and restricted users, and can set other users as administrators.

[0092] Both ordinary users and restricted users can set the operation permissions of other users on the intermediate files except for administrators, and restricted users cannot create the operation permissions for restricted condition type files.

[0093] Preferably, if the administrator wants to prevent certain users from using the secure USB drive, the administrator can set these users as prohibited users in the role permission list; if the administrator wants to restrict certain users' use of the USB drive, the administrator creates a new role R-i, then records the restricted conditions of this role, and then adds these users to the role R-i.

[0094] Preferably, the present invention defines a seven-tuple (U, R, TU, O, TO, f ut , f uo ), and the elements are defined as follows:

[0095] User set U: The set of entities accessing the resources in the secure USB drive, which is the entity operating on the accessed resources, and is formally described as: U = {u1, u2,..., u n};

[0096] Role set R: The set of users with the same type of data access permissions and secure USB drive management permissions, and is formally described as R = {r1, r2,..., r n};

[0097] Role permission type set TU: The set of all possible operation permission values that a certain role r i may have for the secure USB drive, which is called the value range of r, and is formally described as T = {T r | r ∈ R}, where T r = {o(x) | x ∈ R}, where both r and x belong to the role set;

[0098] File set O: The set of files in the secure USB drive. Formal description: O = {o1, o2, …, o n};

[0099] File permission type set TO: The set of all possible operation permissions that a certain user u i has for a certain file o in the secure USB drive, which is called the value range of the binary tuple (u, o). Formal description: T = {T i | u ∈ U, o ∈ O}, where T u,o = {uo(x, y) | x ∈ U, y ∈ O}; u,o

[0100] Information function f ut : U → TU: Used to determine the operation permission value that each user u in the user set i has for the secure USB drive. Formal description:

[0101] Information function f uo : U × O → TO: Used to determine the file permission value that each user u in the user set i has for each file o in the file set O i , formal description:

[0102] Preferably, the relationship between users and roles is many-to-one, where one user corresponds to one role, while one role can correspond to multiple users, and one role corresponds to one role permission. The relationship between files and users is many-to-many. Therefore, the present invention uses an access control matrix A to visually express the relationship between users and files:

[0103] a i,j = f uo (u i , o j )

[0104] The i-th row u of the matrix i represents the operation permissions of user u i for all files in this secure USB drive. The i-th column o of the matrix i represents the operation permissions that file o in this secure USB drive i allows all users to have.

[0105] Preferably, the role permission type set TU of the present invention is specifically defined as: TU = {administrator, prohibited user, ordinary user, restricted condition a type user, restricted condition b type user, ……, restricted condition n type user}, and the file permission type set TO is specifically defined as: TO = {read, read-write, modify, full control, hide}.

[0106] Preferably, based on constructing a seven-tuple (U, R, TU, O, TO, f ut , f uo ), the user set, role set, role permission type set, file set, file permission type set, and related operation functions are defined. In this way, the administrator (high-level role) sets the roles of the secure USB flash drive and the permissions of the roles. At the same time, registered users and shared users can both be assigned different role operation permissions for files, so that while sharing the secure USB flash drive, the access to resources by different users can also be restricted.

[0107] Preferably, the operation permission list of the present invention includes: read, read / write, modify, full control, and hide.

[0108] Based on the corresponding user public key obtained by the shared user and the registration public key generated by the registered user, respectively encrypt the key to obtain the encrypted content:

[0109] Preferably, obtaining the encrypted content specifically includes:

[0110] Based on all user public keys, respectively encrypt the key to obtain multiple shared encryption results;

[0111] Based on the registration public key, encrypt the key to obtain the registration encryption result;

[0112] The registration encryption result and the shared encryption results together form the encrypted content;

[0113] The encrypted content is saved to the corresponding area of the secure information area.

[0114] Preferably, multiple shared encryption results are correspondingly saved to the KM-1 area, KM-2 area,..., KM-n area of the secure information area, where n represents the nth shared user; the registration encryption result is saved to the KM-0 area of the secure information area.

[0115] Saving the encrypted content to the secure information area completes the registration of the secure USB flash drive;

[0116] Preferably, format other sectors of the secure USB flash drive to establish a file system, and encrypt and store the data when writing to the sectors by using the key to complete the registration of the secure USB flash drive.

[0117] Preferably, it further includes: based on the key, use a symmetric encryption algorithm to encrypt the identifier, obtain the encrypted identifier and save it to the secure information area. Only the user with the key can obtain the correct identifier and use the secure USB flash drive correctly.

[0118] Based on the private key of the user to be authenticated, decrypt the encrypted content, and complete the authentication of the secure USB flash drive based on the decryption result:

[0119] Preferably, as Figure 3 shown, the authentication of the secure USB flash drive specifically includes:

[0120] Decrypt the registered encryption result using the private key of the user to be authenticated to obtain the first pre-decryption key;

[0121] Determine whether the correct identifier can be obtained by decrypting the encryption tag using the first pre-decryption key;

[0122] If so, it means that the secure USB drive has been shared with the user to be authenticated and the key has been obtained;

[0123] If not, decrypt the shared encryption result using the private key. After traversing all the shared encryption results, determine whether the correct key can be obtained;

[0124] If so, it means that the user to be authenticated is a shared user and the authentication is passed;

[0125] If not, it means that the authentication fails and the secure USB drive cannot be used.

[0126] After the authentication is passed, obtain the user identity based on the role permission list:

[0127] Preferably, after passing the secure USB drive authentication, the user cannot directly perform data interaction. Decrypt the control area of the secure USB drive using the USB drive key to obtain the role permission list of the secure USB drive;

[0128] Determine the user identity based on the role permission list and the area KM-n where the USB drive key is obtained according to the user to be authenticated.

[0129] Perform corresponding data operations on the data area based on the user identity and the operation permission list:

[0130] Preferably, performing corresponding data operations on the data area specifically includes:

[0131] Determine the user identity of the user to be authenticated based on the role permission list and the shared encryption result;

[0132] If the user identity is an administrator, all data information in the secure USB drive can be operated;

[0133] If the user identity is a general user, perform corresponding operations on the data information in the secure USB drive based on the permission operation list;

[0134] If the user identity is a prohibited user, the secure USB drive cannot be used;

[0135] If the user identity is a restricted user, the data information in the secure USB drive that meets the specified restricted conditions cannot be viewed, created, or operated.

[0136] Preferably, when a shared user stores a file based on the secure USB drive, a shared permission list is generated based on the stored file and stored in the extended metadata area;

[0137] Before other users except the administrator operate on the stored files, it is judged whether they have the operation permission based on the shared permission list. If they have the operation permission, they can perform the corresponding operation; otherwise, they cannot perform the operation.

[0138] Preferably, the shared permission list has the same content as the operation permission list, both including: read, read-write, modify, full control, and hide.

[0139] Embodiment 3

[0140] As Figure 4 shown, a cross-platform secure USB flash drive management system includes: a secure USB flash drive construction module, a permission setting module, a registration module, an authentication module, and a data operation module;

[0141] The secure USB flash drive construction module is used to construct a file system including a secure information area, an extended metadata area, a data area, and a control area and place it into a common USB flash drive to obtain a secure USB flash drive;

[0142] The permission setting module is used to randomly generate a key for the secure USB flash drive, select shared users and set permissions correspondingly, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively;

[0143] The registration module is used to encrypt the key respectively based on the corresponding user public key obtained from the shared user and the registration public key generated by the registered user to obtain encrypted content; the encrypted content is saved to the secure information area to complete the registration of the secure USB flash drive;

[0144] The authentication module is used to decrypt the encrypted content based on the private key of the user to be authenticated and complete the authentication of the secure USB flash drive based on the decryption result;

[0145] The data operation module is used, after authentication is passed, to obtain the user identity based on the role permission list; and perform corresponding data operations on the data area based on the user identity and the operation permission list.

[0146] Preferably, the above modules of the present invention correspond one-to-one with the above implementation methods, and will not be elaborated here one by one.

[0147] Embodiment 4

[0148] The overall framework of the secure USB flash drive of the present invention is as Figure 5 shown, including a UI layer, a business logic layer, a secure USB flash drive driver layer, and an application environment. The overall framework of the secure USB flash drive of the present invention adopts a strategy of separating business processing and display logic and adopts a two-layer hierarchical model of the business logic layer and the UI layer:

[0149] Among them, the UI layer provides a unified interface and operations for users, including functions such as user management, USB flash drive management, and file management;

[0150] The business logic layer is responsible for the business logic of the secure USB flash drive, including the underlying processing logic such as data encryption, file operations, and secure file systems; it also includes the access logic for users, such as secure USB flash drive registration, secure USB flash drive authentication, and data access control.

[0151] The secure USB flash drive driver layer: Due to different underlying hardware and operating systems in the host system, the USB access methods and mechanisms on different platforms are different. In order to adapt to the domestic and X86 environments, the USB drivers for the Linux and Windows operating systems are encapsulated for the Linux and Windows operating systems, providing a unified access interface for implementing the general USB protocol, USB storage protocol, and SCSI commands.

[0152] Preferably, at the underlying level, the access to the USB flash drive is encapsulated for different underlying hardware and operating systems, and a unified interface and data exchange format are defined according to the USB flash drive storage protocol to achieve decoupling between the upper-layer application's operations on the USB flash drive and the underlying platform. At the user level, the cross-platform system solution provides a unified interface and operations, ensuring that users can obtain a consistent application interface and interaction experience on different devices.

[0153] Embodiment 5

[0154] Based on the same inventive concept, the present invention also provides a computer device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;

[0155] The memory is used to store computer programs;

[0156] When the processor is used to execute the program stored in the memory, it can implement a cross-platform secure USB flash drive management method as in Embodiment 1 or 2.

[0157] The electronic device may include: a processor, a communications interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus. The processor can call the logical instructions in the memory to execute a cross-platform secure USB flash drive management method as in Embodiment 1 or 2.

[0158] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods according to the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0159] As can be seen from the above technical solutions, the present invention discloses a cross-platform secure USB flash drive management method and system, which has the following beneficial effects:

[0160] 1. Ensure the confidentiality and integrity of USB flash drive data based on a secure and controllable file system; through an authorization method, only legitimate platforms or users who have passed authentication can access the data in the secure USB flash drive. By setting up a role permission list and an operation permission list, fine-grained access control of USB flash drive data is achieved, so that the data stored on the USB flash drive is protected from unauthorized access, tampering, and malicious attacks.

[0161] 2. Ensure that only users with the corresponding private key can decrypt and access the data in the USB flash drive by randomly generating a key and encrypting the key using public key encryption technology, effectively preventing unauthorized data access and enhancing data confidentiality.

[0162] 3. Based on the role permission list and the operation permission list, the administrator can assign specific operation permissions to different shared users. This mechanism allows for setting detailed access control policies according to the actual needs of users, achieving more refined data protection, and at the same time simplifying the permission management process.

[0163] 4. By configuring independent access permissions for each shared user, the same USB flash drive can be used by multiple users in different levels, which not only ensures the information exchange efficiency during teamwork but also avoids the risk of data leakage caused by excessive permissions.

[0164] 5. Since a standard file system structure and a common encryption algorithm (such as SM4) are adopted, this solution can run on multiple operating system platforms, including but not limited to Windows, Mac OS X, and Linux, etc., greatly improving its application scope and convenience.

[0165] 6. The present invention stores detailed permission configuration information and log records in the control area, facilitating retrospective analysis afterwards, helping to detect potential threats or violations, and enabling timely measures to be taken to address them.

[0166] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference may be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference may be made to the description in the method section.

[0167] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A cross-platform secure USB flash drive management method, characterized in that Including: Construct a file system including a security information area, an extended metadata area, a data area, and a control area and place it into a common USB flash drive to obtain a secure USB flash drive; Randomly generate a key for the secure USB flash drive, select shared users and set permissions correspondingly, and generate a role permission list and an operation permission list and save them to the control area and the extended metadata area respectively; Encrypt the key respectively based on the corresponding user public key obtained from the shared users and the registration public key generated by the registered users to obtain encrypted content; Obtaining the encrypted content specifically includes: Encrypt the key respectively based on all the user public keys to obtain multiple shared encryption results; Encrypt the key based on the registration public key to obtain a registration encryption result; The registration encryption result and the shared encryption results together constitute the encrypted content; The encrypted content is saved to the corresponding area of the security information area; Saving the encrypted content to the security information area completes the registration of the secure USB flash drive; The registration process further includes: Encrypt the identifier based on the key using a symmetric encryption algorithm to obtain an encrypted identifier and save it to the security information area; Decrypt the encrypted content based on the private key of the user to be authenticated, and complete the authentication of the secure USB flash drive based on the decryption result; The authentication of the secure USB flash drive specifically includes: Decrypt the registration encryption result based on the private key of the user to be authenticated to obtain a first pre-decryption key; Judge whether the correct identifier is obtained by decrypting the encrypted identifier based on the first pre-decryption key; If so, it means that the secure USB flash drive is shared with the user to be authenticated and the key is obtained; If not, decrypt the shared encryption results based on the private key, and after traversing all the shared encryption results, judge whether the correct key is obtained; If so, it means that the user to be authenticated is the shared user and the authentication is passed; If not, it means that the authentication fails and the secure USB flash drive cannot be used; After the authentication is passed, obtain the user identity based on the role permission list; Perform corresponding data operations on the data area based on the user identity and the operation permission list; Both the registered user and the shared user can assign different roles to the operation permissions of files.

2. The cross-platform secure USB flash drive management method according to claim 1, wherein The role permission list specifically includes: Administrator: Can use the secure USB flash drive and can change the user role settings; Prohibited user: Cannot use the secure USB flash drive; Ordinary user: Can use the secure USB flash drive and cannot change the user role settings; Restricted user: Can use the secure USB flash drive and cannot view, create, and operate the data information with specified restricted conditions in the secure USB flash drive.

3. The cross-platform secure USB flash drive management method according to claim 2, wherein The administrator is the registered person and has full control rights over the intermediate files generated by the operations of the ordinary users and the restricted users, and can set other users as administrators; Both the ordinary user and the restricted user can set the operation permissions of other users on the intermediate files except the administrator.

4. The cross-platform secure USB flash drive management method according to claim 2, wherein, Performing corresponding data operations on the data area specifically includes: Judge and obtain the user identity of the user to be authenticated based on the role permission list and the shared encryption results; If the user identity is the administrator, all data information in the secure USB flash drive can be operated; If the user identity is the ordinary user, perform corresponding operations on the data information in the security USB flash drive based on the operation permission list; If the user identity is the prohibited user, the security USB flash drive cannot be used; If the user identity is the restricted user, the data information with specified restricted conditions in the security USB flash drive cannot be viewed, created, or operated on.

5. The cross-platform secure USB flash drive management method according to claim 2, wherein, When the shared user stores a file based on the security USB flash drive, generate a shared permission list based on the stored file and store it in the extended metadata area; Before other users other than the administrator operate on the stored file, judge whether they have the operation permission based on the shared permission list. If they have the operation permission, they can perform the corresponding operation; otherwise, they cannot perform the operation.

6. The cross-platform secure USB flash drive management method according to claim 1, characterized in that The extended metadata area stores the verification hash value of the file. When the content of the file changes, calculate the hash value of the corresponding changed file and save it in the file verification area.

7. A cross-platform secure USB flash drive management system, which applies a cross-platform secure USB flash drive management method according to any one of claims 1-6, characterized in that, Including: A security USB flash drive construction module, a permission setting module, a registration module, an authentication module, and a data operation module; The security USB flash drive construction module is used to construct a file system including a security information area, an extended metadata area, a data area, and a control area and place it into an ordinary USB flash drive to obtain a security USB flash drive; The permission setting module is used to randomly generate the key of the security USB flash drive, select shared users and set permissions correspondingly, and generate a role permission list and an operation permission list and save them in the control area and the extended metadata area respectively; The registration module is used to encrypt the key respectively with the corresponding user public key obtained based on the shared user and the registration public key generated by the registered user to obtain the encrypted content; the encrypted content is saved in the security information area to complete the registration of the security USB flash drive; The authentication module is used to decrypt the encrypted content based on the private key of the user to be authenticated and complete the authentication of the security USB flash drive based on the decryption result; The data operation module is used to obtain the user identity based on the role permission list after authentication; perform corresponding data operations on the data area based on the user identity and the operation permission list.

Citation Information

Patent Citations

  • File data safety management system and method

    CN1979511A